Vulnerabilities exploitable today
372,967in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,230
- High8,250
- Medium6,233
- Low615
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-237357.8 HIG24.0%
——7In Saibo Cyber Game Accelerator 3.7.9 there is a local privilege escalation vulnerability. Attackers can use the constructed program to increase user privileges69dCVE-2023-51516—24.0%
——7——CVE-2023-3198—24.0%
——7——CVE-2025-11042—24.0%
——7——CVE-2026-46554—24.0%
——7——CVE-2024-51552—24.0%
——7——CVE-2025-3391—24.0%
——7——CVE-2012-0081—24.0%
——7——CVE-2007-6046—24.0%
——7——CVE-2025-22385—24.0%
——7——CVE-2026-184875.4 MED24.0%
——7A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.15dCVE-2026-27849—24.0%
——7——CVE-2026-175619.8 CRI24.0%
——7Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection.
This issue affects Logsign SIEM: before 6.4.115.17dCVE-2022-29583—24.0%
——7——CVE-2025-60374—24.0%
——7——CVE-2010-0431—24.0%
——7——CVE-2022-41192—24.0%
——7——CVE-2019-12670—24.0%
——7——CVE-2026-6494—24.0%
——7——CVE-2024-23823—24.0%
——7——CVE-2024-10652—24.0%
——7——CVE-2023-23558—24.0%
——7——CVE-2026-55596.3 MED24.0%
——7A vulnerability has been found in AntaresMugisho PyBlade 0.1.8-alpha/0.1.9-alpha. The affected element is the function _is_safe_ast of the file sandbox.py of the component AST Validation. Such manipulation leads to improper neutralization of special elements used in a template engine. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.50dCVE-2024-5177—24.0%
——7——CVE-2025-6171—24.0%
——7——CVE-2018-2500—24.0%
——7——CVE-2026-725649.6 CRI24.0%
——7An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued for a different resource.15dCVE-2026-44888—24.0%
——7——CVE-2016-5504—24.0%
——7——CVE-2025-66202—24.0%
——7——CVE-2024-5646—24.0%
——7——CVE-2021-21911—24.0%
——7——CVE-2008-3890—24.0%
——7——CVE-2026-166907.5 HIG24.0%
——7IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.23dCVE-2026-169269.1 CRI24.0%
——7IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input.18dCVE-2024-13120—24.0%
——7——CVE-2024-51593—24.0%
——7——CVE-2022-47088—24.0%
——7——CVE-2026-89017.2 HIG24.0%
——7The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Submission Data in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload only executes when a CRM API call fails for the submitted form and an administrator subsequently views the error log details modal in the WordPress admin panel.51dCVE-2026-7702—24.0%
——7——